Power distribution network protection resource dynamic allocation method, system and device and storage medium
By constructing a multi-dimensional fusion dataset and attack path prediction model, combined with a multi-objective optimization algorithm, and dynamically allocating protection resources, the problem of response lag in complex network attacks by traditional protection schemes is solved, and efficient security protection of the power distribution network is achieved.
Patent Information
- Application Number
- CN202511228050.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-29
- Publication Date
- 2025-11-11
AI Technical Summary
Traditional security solutions struggle to cope with complex cyberattacks, especially when they are slow to respond to multi-step, multi-stage attacks. Furthermore, existing technologies are inadequate in terms of threat prediction, resource allocation, and response speed, making it difficult to meet the needs of intelligent security protection.
By collecting distribution network data in real time to construct a multi-dimensional fusion dataset, and combining it with a historical attack pattern library and an attack path prediction model, a multi-objective optimization algorithm is used to realize the dynamic allocation and real-time scheduling of protection resources. The resource allocation decision is made using an adaptive weighted multi-objective particle swarm algorithm.
It enables accurate prediction of potential attack paths and efficient resource allocation, improves the response speed and resource utilization efficiency of the protection system, ensures the best protection effect under limited resource conditions, and enhances the safety and stability of the power distribution network.
Smart Images

Figure CN120934875A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of power system network security protection, and in particular to a method, system, device and storage medium for dynamic allocation of protection resources in power distribution networks. Background Technology
[0002] With the rapid advancement of smart power distribution network construction and its continuous improvement in digitalization, power distribution systems are gradually developing towards a highly information-based and networked direction. Within these systems, numerous intelligent terminal devices, communication nodes, and control units are interconnected, forming a complex network topology. Traditional security protection strategies based on static threat models are no longer adequate to adapt to the dynamic and ever-changing network attack environment. Especially with the large-scale deployment of new technologies such as edge computing, IoT devices, 5G communication, and cloud-edge collaboration, the system attack surface has significantly expanded, placing higher demands on the precise allocation and dynamic scheduling of security protection resources.
[0003] Currently, while traditional security solutions possess certain threat detection and defense capabilities, they suffer from response lag when facing multi-step, multi-stage complex attacks. Rule-based static protection strategies, while reliable in defending against known threats, struggle to effectively predict unknown attack patterns and emerging threats. These two approaches differ fundamentally in threat prediction, resource allocation, and response speed, hindering proactive defense, predictive deployment, and intelligent scheduling in protection systems. Furthermore, in complex attack scenarios, such as APT attacks, lateral movement, and privilege escalation attacks, multi-stage attacks often bypass traditional protection mechanisms and cause severe system damage. Existing protection platforms struggle to accurately predict attack paths and pre-configure resources for these attacks. Although some research has attempted to combine threat intelligence with machine learning techniques or build dynamic protection mechanisms based on risk assessment models, limitations in feature extraction, prediction accuracy, and resource scheduling algorithms prevent them from meeting the intelligent security protection needs of large-scale, multi-layered power distribution networks. Summary of the Invention
[0004] In view of the above-mentioned problems, the present invention is proposed.
[0005] Therefore, the technical problem solved by this invention is: how to improve the prevention capability and protection efficiency of power distribution systems in the face of complex network attacks.
[0006] To solve the above-mentioned technical problems, the present invention provides the following technical solution:
[0007] In a first aspect, the present invention provides a method for dynamic allocation of protection resources in a power distribution network, comprising:
[0008] Real-time acquisition of power distribution network operation data to construct a multi-dimensional fusion dataset;
[0009] Based on a multi-dimensional fusion dataset and combined with a historical attack pattern library, potential attack paths are predicted through an attack path prediction model.
[0010] Risk assessments are conducted on predicted potential attack paths, and the protection resource requirements for each area of the distribution network are calculated based on the distribution network topology and the importance of key nodes.
[0011] Based on the risk assessment results and combined with resource constraints, a multi-objective optimization algorithm is used to achieve dynamic allocation and real-time scheduling of protection resources.
[0012] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0013] The prediction of potential attack paths based on a multi-dimensional fusion dataset, combined with a historical attack pattern library, and using an attack path prediction model includes:
[0014] An attack behavior pattern library is constructed based on the current threat characteristics in historical attack data and multi-dimensional fusion datasets: historical attack events are decomposed into time sequence, different attack stages are divided according to time order, and key features including attack methods and target device types are extracted. Similar attack behaviors are classified into attack pattern templates through clustering algorithms, and a pattern knowledge base containing attack sequences, time windows, and success probabilities is established.
[0015] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0016] The method of predicting potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library, using an attack path prediction model, also includes:
[0017] When predicting potential attack paths, the threat features collected in real time are matched with attack templates in the historical attack pattern library. The evolution of attack behavior is learned through deep neural networks. Combined with the distribution network topology and equipment vulnerability information, the probability distribution of each node being attacked is calculated, an attack path probability map is generated, and the most likely attack propagation path and high-risk target nodes are identified.
[0018] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0019] The risk assessment of predicted potential attack paths, combined with the distribution network topology and the importance of key nodes, includes calculating the protection resource requirements for each area of the distribution network, including:
[0020] A multi-dimensional evaluation model is used to calculate the risk value for each predicted attack path. The risk value comprehensively considers the probability of attack success, the coefficient of attack impact range, and the weight of target asset value.
[0021] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0022] The risk assessment of predicted potential attack paths, combined with the distribution network topology and the importance of key nodes, and the calculation of protection resource requirements for each area of the distribution network, also includes:
[0023] The importance of key nodes is determined by network topology analysis, and the node degree centrality and betweenness centrality are used for weighted calculation. The protection resource requirements of each area of the distribution network are calculated by combining the risk value of each attack path and the importance of each node.
[0024] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0025] The process of dynamically allocating and real-time scheduling protective resources based on risk assessment results and resource constraints, using a multi-objective optimization algorithm, includes:
[0026] With the dual objectives of maximizing protection effectiveness and minimizing resource costs, a dual-objective optimization model is established, while constraints including total resource limits, response time constraints, and coverage requirements are set.
[0027] The beneficial effects of this preferred technical solution are as follows: An optimization model is established with the dual objectives of maximizing protection effectiveness and minimizing resource costs. This allows for the reasonable control of protection resource costs while ensuring the safety and protection effectiveness of the distribution network. Constraints such as total resource limits, response time constraints, and coverage requirements ensure that resource allocation is more aligned with actual conditions and needs. This avoids waste caused by excessive resource investment or insufficient protection due to unreasonable resource allocation, achieving rational utilization and efficient allocation of resources.
[0028] As a preferred scheme for the dynamic allocation of protection resources in distribution networks, the following is provided:
[0029] The method of dynamically allocating and real-time scheduling protective resources based on risk assessment results and resource constraints, using a multi-objective optimization algorithm, also includes:
[0030] During resource scheduling, an adaptive weighted multi-objective particle swarm optimization algorithm is used to solve for the optimal allocation scheme. The solution space is searched by updating the particle velocity and position, with the inertial weights adaptively adjusted to dynamically adjust the search strategy according to the fitness of the particles. Pareto optimal solution sets are obtained through non-dominated sorting and congestion distance calculation, thereby completing the resource reallocation decision and realizing the dynamic allocation and real-time scheduling of protection resources.
[0031] The beneficial effects of this preferred technical solution are as follows: the adaptive weighted multi-objective particle swarm optimization algorithm searches the solution space by updating particle velocity and position, and the inertial weights can dynamically adjust the search strategy according to the fitness of the particles. This dynamic adjustment enables the algorithm to have strong global search capabilities in the early stages of the search, avoiding getting trapped in local optima; and strong local search capabilities in the later stages of the search, enabling it to find the optimal solution more accurately. By obtaining the Pareto optimal solution set through non-dominated sorting and crowding distance calculation, multiple feasible optimal solutions are provided for the dynamic allocation and real-time scheduling of defense resources, allowing decision-makers to choose according to the actual situation, thus improving the flexibility and scientific nature of resource allocation decisions.
[0032] Secondly, the present invention provides a dynamic allocation system for power distribution network protection resources, comprising:
[0033] The data fusion and acquisition module is used to collect real-time operational data of the power distribution network and construct a multi-dimensional fusion dataset.
[0034] The attack path prediction module is used to predict potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library, using an attack path prediction model.
[0035] The protection requirement calculation module is used to assess the risk of predicted potential attack paths and calculate the protection resource requirements of each area of the distribution network in combination with the distribution network topology and the importance of key nodes.
[0036] The resource scheduling optimization module is used to dynamically allocate and schedule protection resources in real time based on risk assessment results and resource constraints, using a multi-objective optimization algorithm.
[0037] Thirdly, the present invention provides a computer device, comprising:
[0038] Memory and processor;
[0039] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the dynamic allocation method for power distribution network protection resources are implemented.
[0040] Fourthly, the present invention provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of a method for dynamically allocating protection resources in a power distribution network.
[0041] The beneficial effects of this invention are as follows: The dynamic allocation method for distribution network protection resources has significant practical application value and can effectively solve many problems in distribution network security protection. By collecting operational data in real time to construct a multi-dimensional fusion dataset, combined with a historical attack pattern library and an attack path prediction model, potential attack paths can be accurately predicted. This enables distribution network operators to grasp the possible propagation paths of attacks and high-risk target nodes in advance, and take timely and targeted preventive measures to reduce the losses caused by attacks. In the risk assessment stage, the multi-dimensional assessment model comprehensively considers factors such as the probability of attack success, the scope of impact, and the value of target assets, and combines network topology analysis to determine the importance of key nodes, accurately calculating the protection resource requirements of each area. This helps to rationally allocate protection resources to key areas and nodes, avoid resource waste and unreasonable configuration, and improve the utilization efficiency of protection resources. A multi-objective optimization algorithm is used to realize the dynamic allocation and real-time scheduling of protection resources, aiming to maximize the protection effect and minimize resource costs, while considering constraints such as total resources, response time, and coverage. In actual operation, this method can quickly adjust the allocation of protection resources according to the real-time status of the distribution network and the attack risk, ensuring the best protection effect under limited resource conditions. Furthermore, the adaptive weighted multi-objective particle swarm optimization algorithm can efficiently solve the optimal allocation scheme, providing a strong guarantee for the safe and stable operation of the distribution network and enabling the distribution network to better cope with increasingly complex network attack threats. Attached Figure Description
[0042] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0043] Figure 1 This is an overall flowchart of the dynamic allocation method for power distribution network protection resources provided by the present invention. Detailed Implementation
[0044] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.
[0045] Example 1, referring to Figure 1 This is the first embodiment of the present invention, which provides a method for dynamic allocation of protection resources in a power distribution network, including:
[0046] S1: Collect real-time operational data of the power distribution network and construct a multi-dimensional fusion dataset;
[0047] S2: Based on a multi-dimensional fusion dataset and combined with a historical attack pattern library, potential attack paths are predicted through an attack path prediction model.
[0048] S3: Conduct risk assessments on predicted potential attack paths, and calculate the protection resource requirements for each area of the distribution network based on the distribution network topology and the importance of key nodes;
[0049] S4: Based on the risk assessment results and combined with resource constraints, a multi-objective optimization algorithm is used to achieve dynamic allocation and real-time scheduling of protection resources.
[0050] It should be noted that through steps S1-S4, a complete closed loop of "threat perception - path prediction - risk assessment - resource scheduling" is constructed, realizing intelligent protection against multi-level security threats to the power distribution network. Compared with traditional methods, it has advantages such as high threat prediction accuracy (improved by 82%), superior resource allocation efficiency (covering the entire process of prevention / response / recovery), and fast system response speed (threat identification ≤500ms, resource scheduling ≤2min).
[0051] Example 2, refer to Figure 1 As an embodiment of the present invention, based on the previous embodiment, a method for dynamic allocation of distribution network protection resources is provided, including:
[0052] In this embodiment, the real-time acquisition of distribution network operation data and the construction of a multi-dimensional fusion dataset in step S1 above includes:
[0053] Using a threat situation awareness system, the operation status of the power distribution network is monitored in real time through a multi-source sensor network, collecting multi-dimensional data such as network traffic, equipment status, and security logs. Among them, network traffic data is presented in the form of packet capture files (PCAP) and traffic statistics matrices, equipment status data records operating parameters such as voltage, current, and power in time series format, and security logs store alarm events and abnormal behavior records in structured text format. Through timestamp alignment and data standardization processing, heterogeneous data sources are uniformly converted into standardized feature vectors. A data fusion engine is used to construct a multi-dimensional fusion dataset based on association rules and spatiotemporal correlation analysis for subsequent threat detection and attack path prediction analysis.
[0054] Furthermore, the threat situation awareness system includes a data acquisition layer, a preprocessing layer, and a feature extraction layer. The data acquisition layer deploys network probes, security sensors, and status monitoring devices. Addressing the communication characteristics of multiple protocols coexisting in the distribution network, the network probes employ deep packet inspection technology to parse power-specific protocols such as IEC61850 and Modbus. Security sensors monitor abnormal behavior patterns of the equipment. The preprocessing layer cleans, normalizes, and handles outliers in the raw data. To address the time-varying nature and noise interference of the distribution network data, it uses the Z-score normalization formula for normalization, expressed as:
[0055]
[0056] Where z is the data value after Z-score standardization, μ is the mean, and σ is the standard deviation;
[0057] Outliers are identified using the 3σ criterion, where |x-μ|>3σ. When a data point x meets this condition, it indicates that the deviation from the mean exceeds the normal range and is therefore identified as an outlier. Outliers are marked and isolated, and then corrected using methods such as interpolation, depending on the specific circumstances.
[0058] The feature extraction layer extracts key threat feature vectors using principal component analysis to address the computational complexity issue caused by the excessively high dimensionality of threat features in the power distribution network.
[0059] First, establish the covariance matrix:
[0060]
[0061] Where X is the preprocessed n-dimensional feature matrix, with each row representing a sample and each column representing a feature; n is the number of samples. The covariance matrix C describes the correlation between the features.
[0062] Perform eigenvalue decomposition on the covariance matrix C and calculate its eigenvalues λ. i and the corresponding feature vector v i Eigenvalues represent the importance of each principal component, while eigenvectors represent the orientation of the principal components. Based on the magnitude of the eigenvalues, the top k principal components with a cumulative contribution rate ≥ 85% are selected to construct a dimensionality reduction matrix. The cumulative contribution rate refers to the proportion of the sum of the eigenvalues of the top k principal components to the sum of all eigenvalues; it reflects the amount of information that the top k principal components can explain in the original data. The selected top k eigenvectors are then combined to form a matrix V. k Using the formula Y = XV k The original n-dimensional threat features are reduced to k-dimensional key features. This not only reduces the dimensionality of the data and computational complexity, but also maintains a threat identification accuracy of over 90%, improving computational efficiency by 3 times.
[0063] It should be noted that this step uses edge computing nodes for distributed data processing. To address the issues of data transmission latency and bandwidth limitations in the power distribution network, edge computing nodes are deployed in each substation to achieve local preprocessing and feature extraction, which can reduce the amount of data transmission by 95% and reduce the response latency to the millisecond level.
[0064] In another possible implementation, when constructing a multi-dimensional fusion dataset, IoT devices can be used to expand the data source: in addition to traditional network probes, security sensors, and status monitoring devices, more types of IoT devices, such as smart meters and distributed energy monitors, can be deployed at various key nodes of the power distribution network. Smart meters can collect users' electricity consumption information in real time, including electricity consumption and usage time; distributed energy monitors can monitor the power generation of distributed energy sources such as solar panels and wind turbines. This additional data enriches the dimensions of the dataset, providing more comprehensive information for threat detection and attack path prediction.
[0065] In another possible implementation, external data can be incorporated when constructing the multi-dimensional fusion dataset: combining external data such as meteorological data and geographic information data. Meteorological data (such as temperature, humidity, and wind speed) affects the operating status of power distribution network equipment, and extreme weather may lead to equipment failure or increase the risk of attacks; geographic information data (such as terrain, landforms, and population density) can help analyze the layout of the power distribution network and its surrounding environment, and understand potential threats. By establishing interfaces with external data sources, this data can be acquired in real time and integrated into the multi-dimensional fusion dataset.
[0066] In this embodiment, step S2 above, which predicts potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library using an attack path prediction model, includes:
[0067] A library of attack behavior patterns is constructed based on historical attack data and current threat characteristics in multi-dimensional fusion datasets.
[0068] Specifically, historical attack events are decomposed chronologically, dividing the entire attack process into different attack phases, such as the reconnaissance phase, intrusion phase, and control phase. Simultaneously, key characteristics such as attack methods (e.g., brute-force attacks, vulnerability exploitation) and target device types (e.g., substation equipment, smart meters) are extracted.
[0069] Clustering algorithms (such as K-Means clustering) are used to categorize similar attack behaviors into attack pattern templates. These algorithms group attack events with similar characteristics into a single category, with each category corresponding to an attack pattern template.
[0070] Establish a pattern knowledge base that includes attributes such as attack sequence, time window, and success probability. The attack sequence describes the order of actions at different stages of the attack; the time window represents the possible time range from start to finish of the attack; and the success probability is the likelihood of successfully executing the attack pattern, calculated based on historical data.
[0071] During the prediction process, real-time collected threat features are matched with attack templates in a historical attack pattern library based on similarity. Deep neural networks are used to learn the evolutionary patterns of attack behavior. Combined with information on the distribution network topology and equipment vulnerabilities, the probability distribution of each node being attacked is calculated, generating an attack path probability map to identify the most likely attack propagation paths and high-risk target nodes.
[0072] In another possible implementation, the probability distribution of each node being attacked can be calculated using a Bayesian network-based method.
[0073] Specifically, the analysis focuses on the topology of the power distribution network, the connections between devices, and the causal relationships of attack behaviors. Nodes in the network, such as various devices in the power distribution network (substations, transformers, smart meters, etc.) and attack events (such as reconnaissance and intrusion), are identified as nodes in the Bayesian network. Based on domain knowledge and historical data, directed edges are determined between nodes to represent causal dependencies. For example, if reconnaissance is a precondition for intrusion, then there exists a directed edge from the reconnaissance node to the intrusion node. Using historical attack data and expert knowledge, a conditional probability table (CPT) is determined for each node. The CPT describes the probability of a node taking various values given different combinations of its parent node's values. For example, for an intrusion node, its CPT would give the probability of successful or unsuccessful intrusion under different states of the reconnaissance node (successful reconnaissance, unsuccessful reconnaissance). Real-time collected threat features are input into the Bayesian network as evidence. Using Bayesian inference algorithms (such as variable elimination and belief propagation algorithms), the posterior probability distribution of each node being attacked is calculated. For example, if a certain reconnaissance activity has occurred, the probability of subsequent device nodes being compromised can be calculated using Bayesian inference.
[0074] In another possible implementation, the probability distribution of each node being attacked can also be calculated using a random forest-based method;
[0075] Specifically, features related to node attacks are selected from a multi-dimensional fusion dataset, such as device operating parameters, historical attack records, and device vulnerability information. These features are used as input features to the random forest model. Historical attack data is organized, and the attack status (whether or not a node has been attacked) of each node is used as the target variable. The dataset is divided into training and test sets; the random forest model is trained using the training set data. A random forest is an ensemble learning model composed of multiple decision trees. During training, each decision tree randomly selects a subset of features and samples for training. By continuously learning from the training data, the random forest model can learn the relationship between features and node attacks. Real-time collected feature data from each node is input into the trained random forest model. The model outputs a predicted probability value for each node being attacked. The random forest obtains the final probability distribution by combining the outputs of multiple decision trees (usually by averaging).
[0076] Furthermore, the attack path prediction model adopts a fusion architecture of Long Short-Term Memory Network (LSTM) and Graph Neural Network (GNN) to address the dual characteristics of distribution network attacks, which are both temporally progressive and topologically propagating.
[0077] LSTM is responsible for capturing the temporal characteristics of attack behavior, addressing the issues of long time spans and complex state dependencies in power distribution network attacks. LSTM controls the flow of attack sequence information through forget gates, input gates, and output gates, as shown in the following formula:
[0078] Forgotten Gate:
[0079] f t =σ(W f ·[h t-1 ,x t ]+b f )
[0080] Among them, f t It is the output of the Forgotten Gate, W f It is the weight matrix of the forget gate, used to weight the input x. t Perform a linear transformation; h t-1 b represents the hidden state at the previous moment. f It is the bias vector of the forget gate, and t represents the current time step.
[0081] Input Gate:
[0082] i t =σ(W i ·[h t-1 ,x t ]+b i )
[0083] Among them, i tis the output of the input gate, which is used to determine how much information in the current input x t should be added to the cell state; b i is the bias vector of the input gate.
[0084] Output gate:
[0085] o t = σ(W o ·[h t-1 , x t + b o )
[0086] where o t is the output of the output gate, which is used to determine how much information in the current cell state C t should be output to the hidden state h at the current time step t ; b o is the bias vector of the output gate.
[0087] The cell state update formula is:
[0088] C t = f t × C t-1 + i t × tanh(W C ·[h t-1 , x t + b C )
[0089] where C t represents the cell state at the current time step, W C is the weight matrix used to update the cell state, b C represents the bias vector for updating the cell state.
[0090] The GNN is responsible for modeling the topological relationship of the distribution network, solving the problem of modeling the physical connection and logical dependency relationship between distribution network devices, and updating node features through the message passing mechanism. The formula is:
[0091]
[0092] where is the feature representation of node v at the l + 1 layer, N(v) is the neighbor set of node v, that is, the set of nodes directly connected to node v, σ is the activation function, W (l) is the weight matrix of the l layer, AGG is the aggregation function, represents the feature representation of node u at the l layer, u represents the neighbor node of node v, and N(v) represents the neighbor set of node v.
[0093] The temporal features of the LSTM output and the topological features of the GNN output are fused using an attention mechanism. The formula for calculating the attention weights is:
[0094]
[0095] Where, α ij It is a time-series feature h i With topological feature g j The attention weights between them represent the topological features g during fusion. j For time series features h i The degree of importance; 'a' is a learnable vector used to calculate the attention score; || denotes the vector concatenation operation; h i For the temporal characteristics of the LSTM output, g j The topological features output by the GNN.
[0096] The attention-weighted topological features are added to the temporal features to obtain the fused feature fi, which is used for subsequent attack path prediction. The fused feature is represented as: f i =∑ j α ij g j +h i .
[0097] This integrated architecture enables the prediction accuracy of power distribution network attack paths to reach over 92%, with the prediction time window extended to 30 minutes, providing more accurate and timely decision support for the security protection of the power distribution network.
[0098] It should be noted that the attack path prediction in this step adopts a combination of deep neural networks and time series analysis. Specifically targeting the multi-stage progressive characteristics of attacks on distribution networks, a time window sliding prediction mechanism is designed. The LSTM network captures the temporal propagation pattern of attack behavior in the distribution network, and the graph neural network is combined to model the physical and logical connection relationships between power equipment, thereby improving the dynamic prediction accuracy of attack paths to 92%.
[0099] In another possible implementation, the historical attack pattern library can also be constructed using a decision tree algorithm;
[0100] Specifically, historical attack data is organized into feature vectors and corresponding attack category labels. Feature vectors can include information such as attack occurrence time, source IP address, target device type, and attack method. A decision tree algorithm is then used to train the organized data. The decision tree algorithm divides the data according to the importance of features, forming a tree structure. For example, first, attack patterns are divided into different time periods based on the attack occurrence time, and then further subdivided within each time period based on the target device type. Based on the trained decision tree, different attack patterns are generated. Each pattern corresponds to a leaf node in the decision tree, and the samples in the node have similar attack characteristics. By summarizing and generalizing the characteristics of these samples, an attack pattern template is formed, including attack feature descriptions and the potential impact of the attack.
[0101] In another possible implementation, the historical attack pattern library can also be constructed using the Apriori algorithm;
[0102] Specifically, historical attack data is converted into a transaction dataset, where each transaction represents an attack event, and the items within the transaction represent various attack characteristics. For example, a transaction can be represented as {Attack Time: 8 PM, Attack Method: SQL Injection, Attack Target: Database Server}. The Apriori algorithm is used to mine frequent itemsets, i.e., itemsets that appear more frequently than a set threshold. Through continuous iteration, starting with a single itemset, larger itemsets are gradually generated. For example, frequently occurring combinations of attack times and attack methods are mined, such as {8 PM, SQL Injection}. Association rules are generated based on frequent itemsets. Association rules represent the relationships between different attack characteristics, such as "If the attack occurred at 8 PM, then the attack method is likely SQL Injection". By setting minimum support and minimum confidence thresholds, meaningful association rules are filtered out to form an attack pattern library.
[0103] In this embodiment, step S3 above involves risk assessment of the predicted potential attack paths. Combining the distribution network topology and the importance of key nodes, the calculation of protection resource requirements for each area of the distribution network includes:
[0104] A multi-dimensional assessment model is used for risk assessment, and a risk value is calculated for each predicted attack path, expressed as:
[0105] R i =P i ×I i ×V i
[0106] Among them, R i P represents the risk value. i I represents the probability of a successful attack. i V represents the attack's impact range coefficient. iThe target asset value weight.
[0107] The importance of key nodes is determined through network topology analysis. Node importance is calculated using a weighted average of degree centrality and betweenness centrality, expressed as:
[0108] C j =α×DC j +β×BC j
[0109] Among them, C j DC represents the importance of the j-th node. j For degree centrality, BC j For betweenness centrality, α and β are weighting coefficients.
[0110] After obtaining the risk value of each attack path and the importance of each node, the protection resource requirements for each region are calculated using the following formula:
[0111]
[0112] Where D k Let W be the resource demand for region k. ij Let T be the weight of node j that path i passes through. k The threshold value for the protection capability of region k.
[0113] The threat probability is calculated based on historical attack frequency and current threat strength, and is expressed as follows:
[0114] P=α·f h +β·I c
[0115] Where P represents the threat probability, f h For historical attack frequency, I c This represents the current threat intensity index.
[0116] The scope of influence S is determined based on power flow analysis:
[0117]
[0118] Among them, L i Let C be the load loss of the i-th line. i This represents the cascading failure coefficient.
[0119] The asset value V is assessed using a hierarchical method, comprehensively considering factors such as equipment value, power supply importance, and operation and maintenance costs. The calculation formula is as follows:
[0120] V = w1·V e +w2·V s +w3·V o ,
[0121] Among them, V e For equipment value, V s Due to the importance of power supply, V o For operation and maintenance costs.
[0122] To address uncertainties in the evaluation process, an interval-number fuzzy evaluation method is employed. The evaluation values are represented as interval numbers. Fuzzy calculation using interval number arithmetic rules:
[0123] Addition operation:
[0124] Multiplication operations:
[0125]
[0126] This method can more flexibly handle uncertainties caused by factors such as incomplete data and subjective expert judgment, making the evaluation results more reliable.
[0127] To comprehensively consider expert opinions and the characteristics of the data itself, a combination of expert weights and objective weights is used to calculate the final weight. The expert weight is w. s The calculation formula is:
[0128]
[0129] Where, r i For expert rating, e i This represents the expert experience coefficient.
[0130] Objective weight w o The calculation formula is:
[0131]
[0132] Where, p j Let be the coefficient of variation of index j.
[0133] The final weight w is calculated using the following formula:
[0134] w = λ·w s +(1-λ)·w o
[0135] Where λ is the weight balancing factor.
[0136] The overall risk value R is expressed as:
[0137]
[0138] Where j is the index number, ∑ j This indicates a summation operation on all indicators, w jThis represents the final weight of the j-th indicator. This represents the risk assessment value range for the j-th indicator.
[0139] By calculating the comprehensive risk value, a quantitative indicator that fully reflects the risk status of the distribution network can be obtained, which can be used to solve the problem of multi-source uncertainty in the risk assessment of the distribution network.
[0140] It should be noted that the risk assessment is based on a multi-level evaluation system established using fuzzy hierarchical analysis, specifically addressing the multi-source uncertainty problem in distribution network risk assessment. A three-tiered evaluation architecture—threat-asset-impact—is constructed, clearly demonstrating the relationships between the various stages and levels of the risk assessment. By handling the fuzziness of expert judgments through interval numbers, a risk quantification standard adapted to the operational characteristics of distribution networks is established. This makes the risk assessment results more scientific and accurate, providing strong support for distribution network security protection decisions.
[0141] In another possible implementation, when using a multi-dimensional assessment model for risk assessment, dynamic changes in network topology can also be considered.
[0142] Specifically, a distribution network topology management system is established to record in real time the connection, disconnection, and fault information of equipment, as well as changes in network connections. Simultaneously, Geographic Information System (GIS) and power system simulation software are used to simulate the impact of topology changes on attack propagation; the topology change frequency is defined as the number of times the topology changes per unit time. A higher change frequency may indicate a greater attack risk; topology complexity is calculated by comprehensively measuring indicators such as the number of nodes, the number of connected edges, and network connectivity; a topology change coefficient is introduced into the risk assessment formula, which can be determined based on the topology change frequency and topology complexity, for example, topology change coefficient = 0.6 × topology change frequency coefficient + 0.4 × + 0.4 × topology complexity coefficient.
[0143] In another possible implementation, when using a multi-dimensional assessment model for risk assessment, the attacker's skill level and motivation can also be considered.
[0144] Specifically, this involves analyzing historical attack events to collect information on the attack tools, techniques, and targets used by attackers. Simultaneously, it involves monitoring cybersecurity intelligence platforms and industry reports to understand common attack skill levels and motivational types. Attacker skill levels are categorized into levels such as beginner, intermediate, and advanced, with corresponding weights. For example, a beginner skill level has a weight of 0.3, intermediate 0.6, and advanced 0.9. Different motivational coefficients are determined based on the attacker's motivational type (e.g., economic interests, political motives, destructive purposes). For example, an economic interest motivation coefficient is 0.7, a political motive coefficient is 0.8, and a destructive motive coefficient is 0.9. Finally, a coefficient relating attacker skill level and motivation is introduced, which can be determined based on the skill level weight and the motivational coefficient.
[0145] In this embodiment, step S4 above, based on the risk assessment results and combined with resource constraints, employs a multi-objective optimization algorithm to achieve dynamic allocation and real-time scheduling of protection resources, including:
[0146] With the dual objective functions of maximizing protection effectiveness and minimizing resource costs, a dual-objective optimization model is established to address the problem of limited protection resources in distribution networks and the need for real-time response to threat changes. The model includes:
[0147] Objective function to maximize protection effect:
[0148]
[0149] Resource cost minimization objective function
[0150]
[0151] Where, x ij r represents the number of type j protection resources allocated to region i. i Let e be the risk weight for region i. j For the protection efficiency of resource type j, d ij For the matching degree of resources and risks, c j For the unit cost of resource type j, t ij For transmission time, p j This represents the time cost coefficient.
[0152] The constraints include:
[0153] Total resource limit Response time constraints Coverage
[0154] Require
[0155] in, This indicates the maximum available quantity of protection resources of type j. This represents the maximum allowable response time for region i. Cov represents the minimum coverage requirement for region i. j For the coverage area of resource type j, A i Let i be the area of region i.
[0156] During resource scheduling, an adaptive weighted multi-objective particle swarm optimization algorithm is used to solve for the optimal allocation scheme.
[0157] Specifically, the particle velocity update formula is:
[0158]
[0159] in, This represents the velocity of particle i in the d-th dimension at generation t. Let represent the value of the best position in the history of particle i in the d-th dimension, c1 and c2 are learning factors, and w(t) is the adaptive inertia weight.
[0160] Position update formula:
[0161]
[0162] The adaptive inertia weight is expressed as:
[0163]
[0164] Among them, w max and w min These are the maximum and minimum values of the inertia weight, respectively, and f(x) is the current particle fitness. min f represents the minimum fitness value of all particles in the population. ave The average fitness of the population can be obtained by calculating the Pareto optimal solution set through non-dominated sorting and crowding distance.
[0165] It should be noted that the resource scheduling employs an improved particle swarm optimization algorithm to solve for the optimal allocation scheme. Considering the limited protection resources and the need for real-time response in distribution networks, a fast convergence strategy under multiple constraints is designed. Through adaptive parameter adjustment, such as the use of adaptive inertia weights, the algorithm can dynamically adjust its search strategy based on the fitness of particles, improving search efficiency. Simultaneously, an elite retention mechanism is employed to preserve historically optimal solutions, preventing the algorithm from losing excellent solutions during the search process. Pareto optimal solution sets are obtained through non-dominated sorting and congestion distance calculation, ultimately completing the resource reallocation decision and achieving dynamic allocation and real-time scheduling of protection resources. This effectively addresses the constantly changing threats in the distribution network, improving its security and reliability.
[0166] Example 3: The above is an illustrative scheme of the dynamic allocation method for distribution network protection resources in this embodiment. It should be noted that the technical solution of the dynamic allocation system for distribution network protection resources and the technical solution of the above-described dynamic allocation method for distribution network protection resources belong to the same concept. Details not described in detail in the technical solution of the dynamic allocation system for distribution network protection resources in this embodiment can be found in the description of the technical solution of the above-described dynamic allocation method for distribution network protection resources.
[0167] This embodiment also provides a dynamic allocation system for distribution network protection resources, including:
[0168] The data fusion and acquisition module is used to collect real-time operational data of the power distribution network and construct a multi-dimensional fusion dataset.
[0169] The attack path prediction module is used to predict potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library, using an attack path prediction model.
[0170] The protection requirement calculation module is used to assess the risk of predicted potential attack paths and calculate the protection resource requirements of each area of the distribution network in combination with the distribution network topology and the importance of key nodes.
[0171] The resource scheduling optimization module is used to dynamically allocate and schedule protection resources in real time based on risk assessment results and resource constraints, using a multi-objective optimization algorithm.
[0172] This embodiment also provides an electronic device applicable to the dynamic allocation method of power distribution network protection resources, including:
[0173] The system includes a memory and a processor. The memory stores computer-executable instructions, and the processor executes these instructions to implement the dynamic allocation method for power distribution network protection resources as proposed in the above embodiments.
[0174] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, it implements the dynamic allocation method for power distribution network protection resources as proposed in the above embodiments.
[0175] The storage medium proposed in this embodiment and the dynamic allocation method for power distribution network protection resources proposed in the above embodiments belong to the same inventive concept. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0176] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.
Claims
1. A method for dynamic allocation of protection resources in a power distribution network, characterized in that, include: Real-time acquisition of power distribution network operation data to construct a multi-dimensional fusion dataset; Based on a multi-dimensional fusion dataset and combined with a historical attack pattern library, potential attack paths are predicted through an attack path prediction model. Risk assessments are conducted on predicted potential attack paths, and the protection resource requirements for each area of the distribution network are calculated based on the distribution network topology and the importance of key nodes. Based on the risk assessment results and combined with resource constraints, a multi-objective optimization algorithm is used to achieve dynamic allocation and real-time scheduling of protection resources.
2. The method for dynamic allocation of distribution network protection resources as described in claim 1, characterized in that, The prediction of potential attack paths based on a multi-dimensional fusion dataset, combined with a historical attack pattern library, and using an attack path prediction model includes: An attack behavior pattern library is constructed based on the current threat characteristics in historical attack data and multi-dimensional fusion datasets: historical attack events are decomposed into time sequence, different attack stages are divided according to time order, and key features including attack methods and target device types are extracted. Similar attack behaviors are classified into attack pattern templates through clustering algorithms, and a pattern knowledge base containing attack sequences, time windows, and success probabilities is established.
3. The method for dynamic allocation of distribution network protection resources as described in claim 2, characterized in that, The method of predicting potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library, using an attack path prediction model, also includes: When predicting potential attack paths, the threat features collected in real time are matched with attack templates in the historical attack pattern library. The evolution of attack behavior is learned through deep neural networks. Combined with the distribution network topology and equipment vulnerability information, the probability distribution of each node being attacked is calculated, an attack path probability map is generated, and the most likely attack propagation path and high-risk target nodes are identified.
4. The method for dynamic allocation of distribution network protection resources as described in claim 3, characterized in that, The risk assessment of predicted potential attack paths, combined with the distribution network topology and the importance of key nodes, includes calculating the protection resource requirements for each area of the distribution network, including: A multi-dimensional evaluation model is used to calculate the risk value for each predicted attack path. The risk value comprehensively considers the probability of attack success, the coefficient of attack impact range, and the weight of target asset value.
5. The method for dynamic allocation of protection resources in a power distribution network as described in claim 4, characterized in that, The risk assessment of predicted potential attack paths, combined with the distribution network topology and the importance of key nodes, and the calculation of protection resource requirements for each area of the distribution network, also includes: The importance of key nodes is determined by network topology analysis, and the node degree centrality and betweenness centrality are used for weighted calculation. The protection resource requirements of each area of the distribution network are calculated by combining the risk value of each attack path and the importance of each node.
6. The method for dynamic allocation of protection resources in a power distribution network as described in claim 5, characterized in that, The process of dynamically allocating and real-time scheduling protective resources based on risk assessment results and resource constraints, using a multi-objective optimization algorithm, includes: With the dual objectives of maximizing protection effectiveness and minimizing resource costs, a dual-objective optimization model is established, while constraints including total resource limits, response time constraints, and coverage requirements are set.
7. The method for dynamic allocation of distribution network protection resources as described in claim 6, characterized in that, The method of dynamically allocating and real-time scheduling protective resources based on risk assessment results and resource constraints, using a multi-objective optimization algorithm, also includes: During resource scheduling, an adaptive weighted multi-objective particle swarm optimization algorithm is used to solve for the optimal allocation scheme. The solution space is searched by updating the particle velocity and position, with the inertial weights adaptively adjusted to dynamically adjust the search strategy according to the fitness of the particles. Pareto optimal solution sets are obtained through non-dominated sorting and congestion distance calculation, thereby completing the resource reallocation decision and realizing the dynamic allocation and real-time scheduling of protection resources.
8. A dynamic allocation system for distribution network protection resources, using the method described in any one of claims 1 to 7, characterized in that, include: The data fusion and acquisition module is used to collect real-time operational data of the power distribution network and construct a multi-dimensional fusion dataset. The attack path prediction module is used to predict potential attack paths based on a multi-dimensional fusion dataset and a historical attack pattern library, using an attack path prediction model. The protection requirement calculation module is used to assess the risk of predicted potential attack paths and calculate the protection resource requirements of each area of the distribution network in combination with the distribution network topology and the importance of key nodes. The resource scheduling optimization module is used to dynamically allocate and schedule protection resources in real time based on risk assessment results and resource constraints, using a multi-objective optimization algorithm.
9. An electronic device, characterized in that, include: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, It stores computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.
Citation Information
Cited By
Industrial end node data tamper-proofing method and system based on Internet of Things
CN121125353A
Industrial end node data tamper-proofing method and system based on internet of things
CN121125353B
Power distribution network safety protection resource configuration method, device, equipment and medium
CN122051960A
A power distribution network security protection resource configuration method, device, equipment and medium
CN122051960B